AI agents can one-shot kernel exploits, ending containers as a security boundary

OwariDa · x · 2026-09-23

Security researcher OwariDa and @Markak warn that containers are no longer a real security boundary: a surge of Linux kernel vulnerabilities combined with AI agents has collapsed the barrier to container escapes. Example: CVE-2026-80521 was found with depthfirstlabs' dfs-large1 and a working exploit was generated in one shot with GPT-5.6 Sol — it still works on Ubuntu 26.04. Recommendation: physical separation is best; at minimum use virtualization and don't expose the host kernel's attack surface.

Original post →

More from Infra

Infra channel →